CVE-2026-47340: fallo de gravedad media en Apache DolphinScheduler
Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.5epss 0.5%
probabilidad de explotación
0.5%top 56% de las CVE
explotación observada
noninguna fuente lo reporta
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Productos afectados
Apache Software Foundation · Apache DolphinSchedulerCVEs relacionadas — Apache DolphinScheduler
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-30188HIGHApache DolphinScheduler: Resource File Read And Write VulnerabilityEPSS 6.0%CVE-2022-45462CRITICALApache DolphinScheduler prior to 2.0.5 have command execution vulnerabilityEPSS 2.8%CVE-2022-45875CRITICALApache DolphinScheduler: Remote command execution Vulnerability in script alert pluginEPSS 2.5%CVE-2023-49109CRITICALRemote Code Execution in Apache DolphinschedulerEPSS 2.3%CVE-2024-43202CRITICALApache DolphinScheduler: Remote Code Execution VulnerabilityEPSS 2.1%CVE-2022-25598—Apache DolphinScheduler user registration is vulnerable to ReDoS attacksEPSS 2.0%